GRC Engineer

GovTech· Singapore· greenhouse· veröffentlicht 06.08.2026
Muss:CloudDevOpsCI/CDAISecurityLead

GovTech is the lead agency driving Singapore’s Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government’s capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity.

At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round.

Play a part in Singapore’s vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us today!

Learn more about GovTech at tech.gov.sg.

[What you will be working on]

We are seeking a dynamic individual to be part of the journey in transforming governance, risk, and compliance (GRC) from a traditional oversight function into an integrated and scalable capability that keeps in step with modern IT delivery practices. This role bridges GRC and engineering. The objective is not to become a software engineer who works in compliance, but to become an effective practitioner who leverages engineering thinking to embed GRC seamlessly into DevOps practices and prepare frameworks for emerging AI-driven systems. By bridging regulatory requirements with technical innovation, you will help position Singapore at the forefront of responsible digital government, enabling faster and safer technology deployment that directly benefits citizens in our increasingly AI-integrated future.

Responsibilities

  • Work directly with operational units to understand their challenges, constraints, and needs within their operating context before implementing control requirements.
  • Apply systems thinking to understand how controls interact across processes, platforms, and teams, moving from “this is the control requirement” to “this is how it should operate in practice.”
  • Design and embed GRC practices into system and process development from inception, ensuring governance mechanisms feel natural within product and engineering workflows rather than burdensome.
  • Translate GRC requirements into practical, actionable solutions with stakeholder experience as a primary consideration, ensuring appropriate governance is in place without hindering operational velocity.
  • Analyse delivery workflows, decision latency, and control friction across digital products and platforms to identify systemic risk, operational complexity, and value leakage.
  • Architect reusable control patterns and implement real-time risk and control telemetry using data pipelines, APIs, and analytics platforms to enable continuous automated monitoring and assurance-by-design.
  • Replace retrospective compliance validation with embedded, continuous assurance mechanisms that demonstrate measurable risk outcomes.
  • Implement governance for AI-enabled systems, including model lifecycle controls, decision accountability, data provenance, and human-in-the-loop assurance.
  • Champion the cultural shift toward proactive GRC engineering. Manage key stakeholder relationships across product engineering teams, legacy policy units, and executive leadership to align governance initiatives with broader product roadmaps.

[What we're looking for]

8+ years' experience with either of the two backgrounds:

  • GRC practitioner who understands how GRC can be embedded into systems and workflows to make it practical, operational and scalable; OR
  • Former engineer (security, DevOps, platform, or similar) who are interested in applying structured, systems thinking to modernize GRC processes.

Core Competencies

  • Systems thinking across business, technology, and risk.
  • Structured problem-solving.
  • Pragmatic controls design.
  • Comfort operating in imperfect integration environments.
  • Strong translation skills; clear communication between deep-technical engineering teams, non-technical stakeholders, and policy makers.
  • Strong leadership capability to drive systemic change and influence without relying solely on direct authority.

Technical Literacy

  • Strong foundation in GRC principles with practical understanding of how they apply in modern technology environments.
  • Solid grasp of cloud fundamentals and DevSecOps practices (e.g., CI/CD, Infra as-Code, Policy-as-Code).
  • Familiarity with Product and Platform operating models.
  • Basic scripting or automation experience would be advantageous.

Why This Role Exist

GRC Engineering embeds GRC into systems, measures outcomes continuously, and scales without increasing friction. If you believe GRC should be engineered into how work is done instead of layering on top of it, we would like to speak with you.

What we offer you:

GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation.   

Our employee benefits are based on a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programs. 

We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you. 

Learn more about life inside GovTech at go.gov.sg/GovTechCareers. Stay connected with us on social media at go.gov.sg/ConnectWithGovTech